Skip to content

Cloud API gateway changes break websites with Content Security Policy (CSP) #4326

@vegagmt

Description

@vegagmt

Describe the Bug

Hello Umami Team,

Recently, my website stopped sending analytics data because the tracking script silently switched the data collection endpoint to https://gateway.umami.is.

my CSP (https://cloud.umami.is https://gateway.umami.is https://api-gateway.umami.dev ) what next ?

Since I use a strict Content Security Policy (CSP) on my website, this unannounced change completely blocked all outgoing tracking requests via connect-src.

I understand that you need to optimize your infrastructure, but changing API endpoints without any email notification or changelog warning breaks tracking for everyone who cares about website security.

Could you please notify users in advance about such infrastructure changes in the future? It would prevent sudden data loss for those of us using CSP.

Thank you for your work on Umami!

Database

PostgreSQL

Relevant log output

Which Umami version are you using?

No response

How are you deploying your application?

No response

Which browser are you using?

No response

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions